Briefings · The program
The CMMC pause, explained
On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout, the third-party assessment requirement scheduled for November 10, 2026, and every later milestone with it, while a Reform Task Force reviews the program. The rules underneath did not move: DFARS 252.204-7012, NIST SP 800-171, SPRS scores, and the self-assessments contracts require at award all remain in effect.
The pause · at a glance
The short version
What was suspended is the gate: third-party certification as a condition of award. What was not suspended is the ground: the 110 security requirements, the clauses already in your contracts, self-assessments, annual affirmations, incident reporting, and flow-downs. If an obligation came from a contract clause, it still binds today.
The record
What actually happened
On July 13, 2026, the department announced the immediate suspension of CMMC Phase 2, which would have made certification by a third-party assessment organization (C3PAO) a condition of award for applicable contracts involving controlled unclassified information starting November 10, 2026. All pending and later implementation milestones, including the full-rollout date that would have put the CMMC clause in every applicable solicitation by November 2028, were placed in abeyance with it.
The follow-through was immediate and contractual: contracting officers were directed to include only self-assessment levels (Level 1 Self and Level 2 Self) in new solicitations during the suspension, and to remove Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements from active solicitations and contracts by modification.
In parallel, the department stood up a CMMC Reform Task Force charged with reviewing the whole program, explicitly including whether existing commercial cybersecurity capabilities and self-attestation can carry more of the load. Its report is expected roughly 60 days from the announcement, which lands in mid-September 2026. Industry input was invited through a public request for information, due 12:00 p.m. ET on August 14, 2026.
During the review, the department stated it will continue to enforce cybersecurity compliance against NIST SP 800-171 through self-assessments and select government-led assessments.
Still binding
What still applies, clause by clause
The pause is narrower than the headlines. Here is the obligation-by-obligation picture.
| Obligation | Where it comes from | Status |
|---|---|---|
| 15 basic safeguards for federal contract information | FAR 52.204-21 | ✓In effect |
| All 110 NIST SP 800-171 requirements for CUI | DFARS 252.204-7012 | ✓In effect |
| System security plan and plans of action | NIST SP 800-171 via 252.204-7012 | ✓In effect |
| Cyber incident reporting within 72 hours | DFARS 252.204-7012 | ✓In effect |
| Current self-assessment score in SPRS, no more than three years old | DFARS 252.204-7019 | ✓Checked at award |
| Government assessment access and subcontractor flow-down | DFARS 252.204-7020 | ✓In effect |
| Annual Level 1 and Level 2 self-assessments with affirmations | CMMC Phase 1 (48 CFR rule, in effect since Nov 2025) | ✓In effect |
| C3PAO certification as a condition of award (Level 2) | CMMC Phase 2 | −Suspended |
| Government-led DIBCAC certification assessments (Level 3) | CMMC Phase 2+ | −Suspended |
"Suspended" is not "repealed." The department has said contractors should not assume the suspension is the final disposition of third-party assessment requirements.
Reading it straight
What it means for a small contractor
The deadline moved; your exposure didn't. The 110 requirements are already in your contracts through DFARS 252.204-7012, and your SPRS score is a representation the government relies on at award. The Department of Justice's Civil Cyber-Fraud Initiative has already produced multi-million-dollar False Claims Act settlements over misstated cybersecurity compliance, and that enforcement runs on the clauses, not on CMMC's schedule.
Primes didn't pause. Flow-downs are contractual, and prime contractors reading the same uncertainty tend to keep asking their suppliers for evidence of readiness. A supplier who can show an operating system beats a supplier who can show a plan to have one.
Every reform outcome favors the same position. If third-party assessments return, the queue meets a pool of roughly one hundred authorized C3PAOs and preparation time becomes the scarcest asset. If the program leans harder on self-attestation, the signature on that attestation carries more legal weight, not less, and it needs an implemented, documented, operating system behind it. There is no outcome where the work is wasted.
The honest read: the pause is preparation time. Use it on the system, not the countdown. Our 93-step program exists for exactly that work, and the readiness-gaps briefing shows where that work usually starts.
Straight answers
Asked and answered
Is CMMC dead?
No. The rollout is suspended while the Reform Task Force reviews the program, with a report expected around mid-September 2026. Third-party assessments could return as they were, revised, or replaced by a leaner attestation model, and the department has explicitly not ruled the current model out. The requirements underneath stay binding either way.
Do I still need a SPRS score?
Yes. DFARS 252.204-7019 still requires a current self-assessment score, no more than three years old, posted in SPRS at time of award. The pause did not touch it, and its accuracy is what False Claims Act cases get built on.
My contract already required certification. Now what?
Contracting officers were directed to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from active solicitations and contracts by modification, and to include only self-assessment levels in new ones during the suspension. The change lands contract by contract, so watch your own modifications.
Should we stop preparing?
Stop preparing for a date. Keep preparing the system. Self-assessments, affirmations, and the 110 requirements continue throughout the review, and whatever the task force recommends will still be measured against the same NIST SP 800-171 ground.
Sources
- DoD announcement of the CMMC Phase 2 suspension and Reform Task Force, July 13, 2026 (as reported by DefenseScoop and Federal News Network)
- SBA Office of Advocacy: request for information for the CMMC Reform Task Force (responses due August 14, 2026)
- 32 CFR Part 170, the CMMC Program final rule (Federal Register, October 15, 2024)
- DFARS 252.204-7012, 252.204-7019, and 252.204-7020
Next up
A scoping call is the pause put to work: your contracts, your current posture, and a straight answer on where the preparation time goes first.
Schedule a Demo